start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-287015425-813974205-1193642550-1002\...\Run: [GOOBZOYouTubeAccelerator] => C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2227048 2015-01-30] (GOOBZO)
HKU\S-1-5-18\...\Run: [GoobzoYouTubeAccelerator] => C:\Program Files (x86)\YouTube Accelerator\YouTubeAccelerator.exe [2227048 2015-01-30] (GOOBZO)
GroupPolicy: Group Policy on Chrome detected
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction
ProxyEnable: [S-1-5-21-287015425-813974205-1193642550-1002] => Internet Explorer proxy is enabled.
HKU\S-1-5-21-287015425-813974205-1193642550-1002\Software\Microsoft\Internet Explorer\Main,Start Page = ?type=hppp
SearchScopes: HKU\.DEFAULT -> DefaultScope {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
http://www.mystartsearch.com/web/?utm_s ... earchTerms}
SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
http://www.mystartsearch.com/web/?utm_s ... earchTerms}
SearchScopes: HKU\.DEFAULT -> {2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} URL =
http://www.mystartsearch.com/web/?utm_s ... earchTerms}
SearchScopes: HKU\.DEFAULT -> {E733165D-CBCF-4FDA-883E-ADEF965B476C} URL =
http://www.mystartsearch.com/web/?utm_s ... earchTerms}
SearchScopes: HKU\S-1-5-21-287015425-813974205-1193642550-1002 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = web/?type=dspp&q={searchTerms}
SearchScopes: HKU\S-1-5-21-287015425-813974205-1193642550-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = web/?type=dspp&q={searchTerms}
Winsock: Catalog9 01 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 02 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 03 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 04 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 05 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 06 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 07 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 08 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 09 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 10 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 11 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
Winsock: Catalog9 23 C:\Program Files (x86)\YouTube Accelerator\ytalsp.dll [177512] (GOOBZO)
FF DefaultSearchEngine: mystartsearch
FF SelectedSearchEngine: mystartsearch
FF Homepage: ?type=hppp
FF user.js: detected! => C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\user.js
FF Extension: Youtube Accelerator Helper - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\Extensions\{4C59F3E5-BBD0-4344-8DD2-30866FA0B31E} [2015-01-30]
FF Extension: SourceApp 1.0.1 - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\Extensions\{8dc666b5-f370-4f22-8558-6a137d48eead}.xpi [2015-01-30]
FF Extension: No Name - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\extensions\
fftoolbar2014@etech.com [Not Found]
FF Extension: No Name - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\extensions\
faststartff@gmail.com [Not Found]
FF Extension: No Name - C:\Users\gilles\AppData\Roaming\Mozilla\Firefox\Profiles\o9zyiqs0.default\extensions\{746505DC-0E21-4667-97F8-72EA6BCF5EEF} [Not Found]
CHR HomePage: Default -> ?type=hppp
CHR StartupUrls: Default -> "?type=hppp"
R2 YouTubeAcceleratorService; C:\Program Files (x86)\YouTube Accelerator\YouTubeAcceleratorService.exe [1510248 2015-01-30] (GOOBZO)
2015-01-30 06:14 - 2015-01-30 14:42 - 00000000 ____D () C:\ProgramData\YTAHelper
2015-01-30 06:14 - 2015-01-30 06:14 - 00000000 ____D () C:\Users\Public\Documents\YTAHelper
2015-01-30 06:14 - 2015-01-30 06:14 - 00000000 ____D () C:\Program Files (x86)\YTAHelper
2015-01-30 06:13 - 2015-01-30 06:13 - 00000000 ____D () C:\Users\Public\Documents\ShopperPro
2015-01-30 06:13 - 2015-01-30 06:13 - 00000000 ____D () C:\Users\Public\Documents\GOOBZO
2015-01-30 06:12 - 2015-01-30 14:09 - 00000000 ____D () C:\Program Files (x86)\YouTube Accelerator
2015-01-30 06:12 - 2015-01-30 06:12 - 00172032 _____ (Jin Hui E-mail:
jinhui@jcomsoft.com Web:
http://www.jcomsoft.com) C:\WINDOWS\SysWOW64\AniGIF.ocx
2015-01-30 06:12 - 2015-01-30 06:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YouTube Accelerator
2015-01-30 06:11 - 2015-01-30 06:11 - 00000000 ____D () C:\Users\gilles\AppData\Local\CrashRpt
2015-01-30 06:09 - 2015-01-30 14:50 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\WTools
2015-01-30 06:08 - 2015-01-30 14:45 - 00000000 ____D () C:\Users\gilles\AppData\Roaming\Store
2015-01-30 06:03 - 2015-01-30 13:47 - 00000000 ____D () C:\Program Files (x86)\Ainishare
2015-01-30 06:03 - 2015-01-30 06:03 - 00000000 ____D () C:\WINDOWS\Download
cmd: netsh winsock reset
EmptyTemp:
end